StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,611
of 17,790 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,611 of 17,790 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,144
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0313
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,611 by stars
ChartLatestAffected imagesRadar Score
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

5,483
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

9,320
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

6,326
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
expat@2.5.0-1
no fix listed

Open the chart page →

5,559
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,640
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

14,173
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
expat@2.2.5-4.el8_5.3
0:2.5.0-2.el8_10

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

7,697
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

13,783
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10

Open the chart page →

6,016
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

7,929

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
elautoestopista/raponchi:0.3.0b6f74db9fc81
expat@2.6.2-r0
2.8.1-r0
1
emqx/ecp-ui:2.5.1e33e9816f147
expat@2.5.0-1+deb12u1
no fix listed
1
erenozcan17/react_frontend:v4.56e1b14973f9b
expat@2.7.1-r0
2.8.1-r0
1
erudikaltd/para:latest_stable235e0bc53da2
expat@2.7.4-1
no fix listed
1
erudikaltd/scoold:1.66.0949c56b57e8f
expat@2.7.3-r0
2.8.1-r0
1
escaping/core-keeper-dedicated:latest87fa79255962
expat@2.7.1-2
2.8.2-1~deb13u1
1
esphome/esphome:2026.7.44866347cb5b4
expat@2.7.1-2
2.8.2-1~deb13u1
1
esphome/esphome:2026.8.285abea33854b
expat@2.7.1-2
2.8.2-1~deb13u1
1
esphome/esphome:2024.3.09ab8cc88b28c
expat@2.5.0-1
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
expat@2.5.0-1+deb12u1
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
expat@2.5.0-1+deb12u1
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
expat@2.7.1-2
2.8.2-1~deb13u1
1
esteban1930/frontend-1:1.8.0f9078279632c
expat@2.7.1-r0
2.8.1-r0
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
etherpad/etherpad:2.7.2b723fe5f2594
expat@2.7.5-r0
2.8.1-r0
1
ethpandaops/assertoor:latest1efa2fba6711
expat@2.7.1-2
2.8.2-1~deb13u1
1
evoapicloud/evolution-api:latest966625532d90
expat@2.7.5-r0
2.8.1-r0
1
evoapicloud/evolution-manager:latestcbfeb314afb9
expat@2.7.3-r0
2.8.1-r0
1
extrim/perlite:1.5.99cb7eb5598b6
expat@2.7.0-r0
2.8.1-r0
1
falcosecurity/event-generator:latest932956d86c99
expat@2.5.0-1+deb12u2
no fix listed
1
featurehub/dacha2:1.9.1c8d5551b5e40
expat@2.7.0-r0
2.8.1-r0
1
featurehub/edge:1.9.198ad426737f6
expat@2.7.0-r0
2.8.1-r0
1
featurehub/mr:1.9.1477d8bf771a9
expat@2.7.0-r0
2.8.1-r0
1
felipecs8/app-db-connection-test:v129e06c9c6385
expat@2.5.0-1+deb12u1
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
expat@2.5.0-1
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
expat@2.7.1-2
2.8.2-1~deb13u1
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
expat@2.2.9-1ubuntu0.8
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
expat@2.5.0-1+deb12u1
no fix listed
1
fiware/mintaka:0.7.092a3c5cf43c0
expat@2.2.5-8.el8
0:2.5.0-2.el8_10
1
fiware/mintaka:latestefc6793388cc
expat@2.2.5-8.el8
0:2.5.0-2.el8_10
1
fiware/orion-ld:1.10.03c490a746f65
expat@2.2.5-17.el8_10
0:2.5.0-2.el8_10
1
flanksource/batch-runner:v1.0.44689687a7cf95
expat@2.6.1-2ubuntu0.3
no fix listed
1
flashcatcloud/categraf:latest42e6ab16472e
expat@2.6.1-2ubuntu0.4
no fix listed
1
flowable/flowable-rest:7.1.0b7ae287502cd
expat@2.6.3-r0
2.8.1-r0
1
fluent/fluent-bit:4.0-debuge76397ef3983
expat@2.5.0-1+deb12u2
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
expat@2.2.9-1ubuntu0.6
no fix listed
1
fnzv/dump1090:latestb3079b95c336
expat@2.4.7-1ubuntu0.2
no fix listed
1
folioci/edge-connexion:latestb4863d135524
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-agreements:latest29c3f233a498
expat@2.6.2-r0
2.8.1-r0
1
folioci/mod-authtoken:latest995a25a33133
expat@2.7.4-r0
2.8.1-r0
1
folioci/mod-copycat:latest1513fad2b799
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-courses:latest68ca414f5596
expat@2.7.4-r0
2.8.1-r0
1
folioci/mod-ebsconet:latest3ae8cb99daa3
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-eusage-reports:latest15de67587091
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-ldp:latestb55696fd9065
expat@2.7.0-r0
2.8.1-r0
1
folioci/mod-licenses:latestcfd6109bf477
expat@2.6.2-r0
2.8.1-r0
1
folioci/mod-login:latest88de493f86db
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-login-saml:latest5f3358ccaa0f
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-ncip:latest8ed83674352b
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-oa:latestae3b069d4ba5
expat@2.6.2-r0
2.8.1-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.